5.4
CVE-2026-73039
- EPSS 0.22%
- Veröffentlicht 13.08.2026 21:34:04
- Zuletzt bearbeitet 14.08.2026 19:18:00
- CVE-Watchlists
- Unerledigt
streama Insecure Direct Object Reference via ViewingStatusController
streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching dashboards by supplying arbitrary primary keys without ownership verification.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerstreamaserver
≫
Produkt
streama
Default Statusaffected
Version
0
Version <
1fa79534ee09e25f2473cc4787b106996008a442
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.13 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://github.com/streamaserver/streama
https://github.com/streamaserver/streama/issues/1170
https://github.com/streamaserver/streama/commit/1fa79534ee09e25f2473cc4787b106996008a442
https://www.vulncheck.com/advisories/streama-insecure-direct-object-reference-via-viewingstatuscontroller